Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-3279
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3279

Description:
PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC domain, which allows remote attackers to create and execute functions, as demonstrated by functions that perform local brute-force password guessing attacks, which may evade intrusion detection.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/35144

OSVDB
  40900

MISC
  http://www.portcullis.co.uk/uplds/whitepapers/Having_Fun_With_PostgreSQL.pdf
  http://www.leidecker.info/pgshell/Having_Fun_With_PostgreSQL.txt

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2007:188

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/471541/100/0/threaded


Return to the previous page.